Privacy Policy

Effective date: September 30, 2026

This Privacy Policy explains how CuraeAI Inc. ("CuraeAI," "we," "us" or "our") collects, uses, shares, keeps and protects personal information, and the choices and rights you have. It applies to everyone whose information we handle through the CuraeAI service (the "Service"): people with a CuraeAI account, people who connect records through Curae Connect inside another app, people who view information someone shows them with a Curae share code, visitors to curaeai.com, and developers who use our developer platform.

Consumer health data is also covered by our Consumer Health Data Privacy Policy, and the AI Processing Disclosure explains our features that use artificial intelligence. Both are part of how we describe our practices, and you can read them at any time.

The short version

  • Your health record is yours. We collect health information to build your personal health record and to do what you ask with it.
  • We don't sell your data. We don't sell, license or otherwise monetize individual patient data, and we don't use your information for advertising.
  • You control sharing. We share your health information only when you tell us to, with the people and apps you choose, until the date you choose, and with the service providers that run the Service for us.
  • You can leave. You can disconnect a source, delete what it imported, or delete your account at any time. Section 9 explains exactly what deletion removes and what we keep.
  • No tracking. We don't use product analytics, and we set only the cookies the Service needs to work (Section 11).
  • Questions or requests: privacy@curaeai.com. Don't include health information in an email to us.

1. Who we are

CuraeAI Inc. is a Delaware corporation that operates online. We decide how and why your personal information is processed in the Service, and we are responsible for it. You can reach us about privacy at privacy@curaeai.com.

2. Where the Service is offered and where your information is kept

2.1. We offer the Service in the United States only, and we store and process the information in the Service in the United States: our systems run on Amazon Web Services in its US East (Northern Virginia) region, and copies of our tamper-evident audit records are also kept in its US West (Oregon) region.

2.2. Privacy terms for people outside the United States are published as regional supplements to this policy. No regional supplement is in effect.

3. Our role, and the laws that apply to your record

3.1. Your personal health record. For the account you create and the records you gather in it, CuraeAI is a vendor of personal health records: a company that keeps a health record managed and controlled by you. The federal Health Insurance Portability and Accountability Act ("HIPAA") does not apply to the personal record you keep with us, so we do not give you a HIPAA Notice of Privacy Practices. Instead, this Privacy Policy, our Consumer Health Data Privacy Policy, the Federal Trade Commission's Health Breach Notification Rule (16 C.F.R. Part 318) and the state laws described in Section 14 govern how we handle it.

3.2. Records you import. When you connect a patient portal, directly or through Curae Connect inside another app, the health system discloses your records to us because you asked it to. Those copies are part of your personal health record under this policy, and you can delete them, or your account, at any time. The health system keeps its own records under its own obligations.

4. Information we collect

We collect only what the Service needs to do what you ask of it. The table in Section 14.1 groups the same information into the categories California law uses.

4.1. Account and profile information (from you)

  • When you sign up: your email address, first and last name, date of birth, and — if you choose to give them — your sex, phone number and an invitation code. If you sign up with a Google account, Google gives us your name and email address.
  • If you choose to add them in your profile: middle name, suffix, home and work address, emergency contact, occupation, languages spoken, race, ethnicity, ancestry, marital status, education level, income range, sexual orientation, a profile photo, and your language, time-zone and notification preferences. We remove the location, device and time details embedded in a photo before we store it.

4.2. Sign-in and security information

  • Your password is held by our own sign-in system in a form that cannot be read back. We keep the public part of any passkey you register, the setup of any authenticator app you add, and which Google account you have linked.
  • Records of your sign-ins and sessions: when they began and ended, and the way you signed in; and, where a device proves a session with a key it holds, a fingerprint of that key.
  • Verification codes we email you when you sign up with an email address or change it, and records of the security choices you make.

4.3. Health information

  • From health systems you connect. When you connect a patient portal (we support portals built on Epic, Oracle Health (Cerner), athenahealth and eClinicalWorks), we import the records the health system makes available to you through it, which can include: your demographic details and identifiers such as medical record and insurance member numbers; conditions and diagnoses; medications, prescriptions, dispensing and administrations; allergies; laboratory and other test results, vital signs and imaging studies; immunizations; procedures; visits and appointments; clinical notes and other documents and their attachments; care plans, care teams and goals; devices; family health history and related persons; questionnaire answers; insurance coverage, claims and explanations of benefits; and consent, referral and other records the health system includes.
  • From you. Documents and images you upload (for example PDFs, photos, scans, DICOM images, text and HL7 files), details you add to them, your answers to health questionnaires (including mood and anxiety questionnaires), and information you enter yourself, such as conditions and family health history.
  • Information we derive. Calculated scores and estimates shown in the Service (such as Health Reserve and hereditary-risk information), labels that identify sensitive kinds of records, and — where the features are switched on — summaries and extracted findings produced by artificial intelligence, as the AI Processing Disclosure describes.
  • Sensitive information in records. Your records may contain information about sexual and reproductive health, mental health, substance use (including records protected by 42 C.F.R. Part 2), genetic testing, and other sensitive matters. We label several of these kinds of information so that the Service applies extra protection when you share.

4.4. Information about other people

  • Relatives. If you build a family health history, you may give us a relative's name, sex, birth year, health conditions, age when a condition began, and whether and why they died. Only give us information you are allowed to share.
  • People in your records. Records from health systems can name clinicians, emergency contacts and related persons.
  • Contacts. When you connect with another CuraeAI user as a contact, we record the connection.

When you share with someone, connect an app or accept one of our documents, we record what you chose, when, for whom and until when, together with the authorization you signed. We also record each time your health information is disclosed to a contact, a person who views a share code or an app, and to whom; for a relative, we record the authorization that sends them a copy.

4.6. Technical and usage information

  • Every request to our servers carries your IP address and your browser's description of itself. We record these, with the time and the action taken, in our security and audit records.
  • Cookies and similar technologies are described in Section 11. We do not use product analytics.
  • We do not collect your precise location, and we do not use fingerprinting.

4.7. People who view a share code

If someone shows you information with a Curae share code, we collect your email address and confirm it with a code we email you, and we record when you viewed the information and your IP address. If you tick Remember me on this browser for 30 days, a cookie lets you skip the emailed code on that browser for that time (Section 11.1). We use this information to protect the share, to show the person who shared it who viewed it, and to tell you if they ask for their information to be deleted.

4.8. Requests and messages

If you ask us to add a health system to the Service, we record the name you give us and what you searched for. If you email us, we receive your message and anything you attach.

4.9. Developers

If you create a developer account, we collect your work email address, your organization's name, your password (held as described in Section 4.2), the settings and contact details you add (such as a display name, logo, support link and contact email), your API keys (we keep only a one-way fingerprint of each key), the addresses of your webhook endpoints, the information our review of your app records before it can receive real health information (such as your organization's legal name and the name and logo we show people), your app's website domain and the record that proves you control it, the return addresses you register for Curae Connect, and the IP address from which you signed up.

4.10. Apps you use with Curae Connect

When an app you use starts a Curae Connect connection, the app gives us the identifier it uses for you. It does not give us your email address, and the Curae Connect screens neither ask for one nor show one; we learn your email address only if you finish setting up a full CuraeAI account.

4.11. Payments, and what we do not ask for

Nothing in the Service has a price today. If you pay for a feature, you pay through a payment processor, which receives your payment details; we receive a record of what you bought, the amount, the date and the last four digits of your card, never the full card number. We do not ask for your Social Security number (although a record imported from a health system may contain identifiers the health system includes). We do not send text messages, and we do not collect biometric identifiers.

5. How we use information

We use personal information to:

  1. Provide the Service you ask for: create and secure your account, import and organize your records, show them to you, calculate scores, generate the AI summaries you request where AI features are switched on, and send you the notifications you choose.
  2. Carry out the sharing you direct (Section 6.1).
  3. Keep the Service and your information secure: authenticate you, detect and stop fraud, abuse and security incidents, and keep audit records of who accessed and disclosed health information.
  4. Support you when you contact us.
  5. Operate and improve the Service: monitor its performance and fix errors.
  6. Communicate with you about your account, security, and changes to our documents. We do not send marketing email.
  7. Meet our legal obligations and protect rights: comply with the law and valid legal process, enforce our Terms, and establish or defend legal claims.

We do not use your information for advertising, we do not sell it, we do not use it for insurance underwriting, employment decisions or credit decisions, and we do not use it to train artificial-intelligence models. We do not use your information to make decisions about you that produce legal or similarly significant effects. We use personal information for a purpose not described here only with your consent.

6. How we share information

6.1. When you tell us to

We share your health information with the people and apps you choose, in the ways the Service offers:

  • Contacts and other people you give access to see the parts of your record you selected, until the end date you chose (at most one year) or until you stop sharing.
  • A person you show a share code to can see what you chose, once, for up to 5 minutes, after confirming their email address. The code works once and stops working when you close the screen that shows it. A share code never shows your photo or the personal details in your record, such as your date of birth; it shows your initials unless you choose to hide your name or to show your first or full name.
  • Relatives you share family health history with receive a copy, in their own record, of the family health history you choose to share with them. We update it until the end date you chose (at most one year); on that date, or earlier if you stop sharing, it leaves their record, and they keep only what they added to their own family history.
  • Apps you connect through Curae Connect receive the kinds of records, and the period of records, you approve on the authorization screen, until the end date shown there (at most one year). Each app is operated by its developer under its own privacy policy; when CuraeAI publishes an app, such as VibeCheck, CuraeAI is that developer, and the app's own privacy policy describes what it does with what it receives. We record each disclosure to an app, and you can see which apps have received your information.
  • Health systems you connect receive your authorization and our requests to import your records.

Each share is an authorization you sign by tapping the button that shares; its full text is our Sharing Authorization, and, if you sign in to the Service, you can view and download each one under Consents. When you delete your account, or delete a health system's records with Delete Records, we tell the people and apps that received that information, as Sections 9.2 and 9.5 describe.

6.2. Service providers

We use the following companies to run the Service. Each processes personal information only on our instructions, under a contract that limits its use:

ProviderWhat they do for usWhat they receive
Amazon Web ServicesHosting, databases, storage, message streaming, encryption keys and sending our emails; our own sign-in and authorization systems run thereAll information in the Service, encrypted at rest, under a business associate agreement with us
Microsoft (Azure)Provides the servers on which CuraeAI runs its own AI models for the AI features described in the AI Processing DisclosureThe parts of your records a feature needs, as the AI Processing Disclosure describes, only while those features are switched on, under a business associate agreement with us
MongoDB AtlasHosts our directory of health systemsThe words you type to search the directory for a health system, without your name, email address or account

Our sign-in system and our authorization system run on our own infrastructure at Amazon Web Services; no outside identity company receives your information. If you sign in with Google, Google provides that sign-in as the provider you chose, under its own terms. When we look up medical terms in public terminology services run by the U.S. National Library of Medicine and the Regenstrief Institute, we send only standard medical terms and codes — never information that identifies you.

Our company email is handled by an email hosting provider, which receives the messages you send to privacy@curaeai.com, support@curaeai.com or security@curaeai.com and our replies. It is not a channel for health information: don't include health information in an email to us.

We may disclose information when we believe in good faith that the law requires it — for example, in response to a subpoena, court order or other valid legal process — or when it is necessary to prevent imminent harm to someone's life or safety, to investigate or prevent fraud or security incidents, or to establish, exercise or defend legal claims. Unless the law or the circumstances forbid it, we tell you before we disclose your health information in response to legal process, so that you can object.

6.4. If our business changes

If CuraeAI is involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, personal information may be transferred as part of that transaction, but only to a party that agrees to handle it under this Privacy Policy and our Consumer Health Data Privacy Policy. Information transferred that way stays subject to those policies unless you agree to a different one.

6.5. Not for sale

We do not sell, license or otherwise monetize individual-level data, whether it identifies the person or has been pseudonymized. We do not share personal information with advertisers or data brokers or for targeted advertising, and we do not use or disclose it for insurance underwriting, employment decisions or marketing.

7. Your choices

  • Sharing. You can see every share and its end date, stop any share, and view or download the authorization you signed, in the Service under Consents. Consents also lists each share code you showed and, once it is viewed, the email address of the person who viewed it. A share code stops working when you close the screen that shows it.
  • Sources. You can disconnect a health system at any time. Curae then stops importing from it, cancels any import in progress and deletes the access your patient portal gave us; where the health system supports revoking that access, and it has not already expired or been replaced by reconnecting, we also ask the health system to revoke it. The records already imported stay in your record until you delete them with Delete Records (Section 9.5).
  • Notifications. You can choose which notifications you receive in Settings.
  • Consent. You can withdraw your consent to our collection of consumer health data in Settings. Because the Service cannot keep a health record without it, withdrawing closes your account and deletes your health information as Section 9.2 describes.
  • Your account. You can delete your account in Settings.
  • Accounts made through Curae Connect. If your account was made through Curae Connect and you have not finished setting up a full account, you cannot sign in to the Service, so the controls above are not available to you. You can stop sharing with the app at any time in one of two ways: open Curae Connect from the app and choose Manage sharing, then Stop sharing; or use the app's own control for stopping sharing, which we require every app to provide. We require the app to delete what it received within 24 hours after you stop. In Manage sharing you can also see and download each authorization you signed, and delete your account: when you confirm on that screen, sharing with the app ends at once and your health information is deleted as Section 9.2 describes, which also withdraws your consent to our collection of consumer health data. For any other request under Section 8, email privacy@curaeai.com and name the app you used.

8. Your rights, and how to use them

8.1. Your rights. Whatever state you live in, you can ask us to:

  • confirm whether we process your personal information, and access it — you can see your records in the Service at any time, and you can ask us for a copy of the personal information we hold about you, in a portable format where that is technically possible;
  • know the categories of personal information we collect, where it comes from, why we use it, and the categories of recipients, as this policy describes, and receive a list of the third parties to which we have disclosed your health information;
  • correct inaccurate personal information — you can edit your profile and the information you entered yourself in the Service; records from a health system must be corrected by that health system;
  • delete personal information, as Section 9 describes;
  • withdraw consent you have given; and
  • appeal a decision we make about your request.

We do not sell personal information, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of in those respects.

8.2. How to make a request. Use the controls in the Service, or email privacy@curaeai.com from the email address on your account. A request by email to delete your account starts the same confirmation as deleting it in Settings (Section 9.2). If you do not have an account — for example, you viewed a share code — email us from the address we have for you. If your account was made through Curae Connect and you have not finished setting up a full account, use Manage sharing in Curae Connect to stop sharing, get a copy of an authorization or delete your account (Section 7); for any other request, email us and name the app you used. Don't include health information in an email to us: tell us what you want us to do, and sign in to the Service to see, share or delete your records. Because the Service operates only online and you have an account with us, email is the way to reach us with a request. To protect your information, we verify that a request comes from you — normally by asking you to confirm it from, or sign in with, your account, or, for an account made through Curae Connect, by asking the app's developer to confirm the identifier the app uses for you — and we do not ask for more information than we need to do that. You can ask someone to make a request for you as your authorized agent; we ask the agent for your signed permission and may ask you to confirm your identity with us directly, unless the agent holds a valid power of attorney.

8.3. Timing and cost. We respond within 45 days after we receive your request. If we need more time, we tell you within those 45 days and take up to another 45 days. Requests are free, up to twice in any 12 months; after that, or if a request is manifestly unfounded or excessive, we may decline it or charge a reasonable fee, and we tell you why.

8.4. Appeals. If we decline to act on your request, in whole or in part, we tell you why and how to appeal. To appeal, reply to our decision or email privacy@curaeai.com with the subject line "Privacy Appeal" within 45 days after you receive it. We decide your appeal within 45 days (or within the shorter time your state's law requires) and explain our decision in writing. If we deny your appeal, we tell you how to contact the attorney general of your state.

8.5. No discrimination. We do not deny you the Service, charge you a different price or give you a different quality of service because you exercised a privacy right.

9. How long we keep information, and what deleting your account does

9.1. Retention. We keep personal information only as long as we need it for the purposes in Section 5, or as the law requires:

InformationHow long we keep it
Account and profile informationWhile your account exists. Section 9.2 explains what happens when you delete your account.
Records imported from a health systemUntil you delete them (Delete Records, after disconnecting the health system) or delete your account; they are then erased within 30 days of your request.
Documents, images and your profile photoUntil you delete your account, or, for documents imported from a health system, until you delete that health system's records. If you replace or remove your profile photo, we erase every stored version of the earlier one.
Records of the consents, sharing authorizations and documents you accepted or signedWhile your account exists, and for 6 years after it is deleted, without your name or email address; each keeps the words you signed, which name the person or app you shared with. An authorization that another person's record still refers to, or that an app connection records, is kept as long as that record is kept.
Records of the app connections you authorizedWhile the app connection exists and after it ends, with no set end, because they record what we disclosed to each app (Section 9.3).
Records of access to and disclosure of your health information, and of changes to consentsFrom 14 days to 6 years in our database, depending on the kind of record, and records of changes to a consent for as long as the consent is in effect and 3 years after; a copy that replaces direct identifiers with a pseudonym is kept for 6 years (24 months for records of routine service use) in write-once storage. After your account is deleted, the key that links these records to you is destroyed.
Share codesA share code works until it is viewed once, you close the screen that shows it, or 15 minutes pass, whichever comes first. The record that it existed, and who viewed it and when, is kept with the authorization you signed and the record of the viewing, as the rows above describe.
Email addresses of people who viewed a share codeWith the record of the viewing, as the access and disclosure row describes. A "Remember me" cookie lasts 30 days.
NotificationsRead notifications are deleted once they are 90 days old. Unread notifications are kept until you delete them.
Sign-in sessionsA browser session ends after one hour without activity and at most 12 hours after sign-in. Session records are deleted at least 24 hours after the session ends.
Verification codesTen minutes; a password-reset authorization lasts one hour.
Copies in our internal message streamUp to 30 days.
Database backups30 days for the database that holds your records; 14 days for the database of our sign-in and authorization systems; 3 days for snapshots of our cache.
Service logs30 days for application and firewall logs; 90 days for web access and network logs; 365 days for the logs of our audit-record pipeline, which carry pseudonyms instead of your identity.
Records of our personnel's administrative activity365 days for records of administrative sessions on our servers; about 7 years for records of administrative activity on our cloud accounts.
Records of a security incident, such as the list of people a notice goes to450 days, or longer while a court order or an open investigation requires it (Section 9.3). The record that we sent you a notice about a security incident (which notice, when, and whether it was delivered) is kept to show that we notified you.
Account deletion requestsThe dates of the request and of its completion, for 6 years after deletion, without your email address.
Developer account informationWhile the developer account exists. When an app is retired, its name, business contact, logo and support links are erased once no deletion notice about it can still be owed; the records of what each app received are kept as the app-connection row describes.

9.2. What deleting your account does. You ask to delete your account in Settings, or by email (Section 8.2). We email you a link to confirm, which works for 24 hours. When you confirm:

  • right away, you and everyone you shared with lose access: we end every sign-in session, every share, every connection to a health system and every connected app's access, remove you from other people's contacts, and tell each person and app that received your health information, including an app you no longer shared with, that you asked for it to be deleted (each app must delete what it received within 24 hours); and
  • within 30 days of your request, we permanently erase your health information and your account: the records imported from your health systems, your documents, images and profile photos (every stored version of each), the information you entered yourself in your record, scores and other information derived from your records, earlier versions of edited records, and your identity in our sign-in system. We email you when the erasure is complete.

Until the date your information is erased, which we show you when you confirm and in our email, your email address cannot be used to create a new Curae account; after that date, you can sign up with it again, and the new account starts without your earlier information.

If you did not ask for the deletion, email security@curaeai.com right away, and don't include health information in your email; until the erasure begins, we can stop it and restore your account. Withdrawing your consent to our collection of consumer health data (Section 7), or declining an updated version of our documents, starts the same process.

9.3. What we keep after you delete your account. We keep only:

  • records of access to and disclosure of your health information, including who viewed each share code you showed and when, for the periods in Section 9.1, with the key that links them to you destroyed, because they are used to detect and investigate misuse;
  • a record that your account existed and when it was closed and erased, kept under an internal number, without your name, email address or any other detail about you, for as long as the records in this section that refer to it are kept; and, for 6 years, the record of your deletion request and of the documents you accepted and the sharing you authorized (Section 9.1);
  • records of each app connection you authorized — which app, what it could read and when, the app's own identifier for you, and the details of each export it requested — because they record what we disclosed to that app;
  • records other people keep that name you, such as a power of attorney that names you or a share someone gave you, and a health-care provider's record of the roles you held in its workspace;
  • copies in database backups and in our internal message stream, until they expire (Section 9.1);
  • copies of family health history you shared into a relative's record, which leave their record when you confirm and are erased 30 days later;
  • the family tree you built — each relative you added, with their name, sex, birth and death years, whether they have died, cause of death and ancestry, how they are related, and the place where you appeared, without your name — because relatives who use Curae can share the same tree; the health history you recorded about them is erased with your record;
  • the record that we sent you a notice about a security incident, if we sent one (Section 9.1); and
  • information a court order or an open security investigation requires us to keep, only that information and only while it is required; our final email tells you when this applies.

9.4. Health systems keep their records. Deleting information in CuraeAI does not delete a health system's own records of your care.

9.5. Deleting the records from one health system. After you disconnect a health system, Delete Records permanently erases the records imported from it, and anything derived from them, within 30 days of your request; a record that another health system you connected also sent stays, as that health system's record. After we erase them, and after a pause of at least an hour so that any request that was reading them has finished, we tell the people you shared health records with, and anyone one of those records was disclosed to, that you asked for them to be deleted, and we tell each app that received any of those records, whether or not you still share with it, which of them to delete.

10. How we protect information

We use administrative, technical and physical safeguards designed for health information, including:

  • encryption of information between your browser and our servers (TLS), and of our servers' connections to our databases, caches and message stream;
  • encryption of stored information with keys we manage in Amazon Web Services' key management service, rotated automatically, and additional encryption of especially sensitive items such as the tokens that connect us to your health systems;
  • separation of each person's information in our database, and an authorization system that checks each access against the permissions and consents in effect;
  • strong sign-in for every account that can see health information (a passkey, a password plus an authenticator app, or a Google account protected by Google's own security);
  • tamper-evident, write-once audit records of access to and disclosure of health information;
  • a web application firewall, malware scanning of files you upload, and logging of administrative activity on our cloud accounts; and
  • limits on our personnel's access to health information, and records of that access.

No system is perfectly secure, and we cannot guarantee the security of information. Please protect your sign-in credentials.

11. Cookies and similar technologies

11.1. Cookies we need. The Service uses a small number of cookies that it cannot work without. They are set only by the Service at app.curaeai.com and, for developers, by our developer platform at platform.curaeai.com. Each is sent back only to the address that set it, is not readable by scripts on the page, and is not used to track you across other websites. Our website at curaeai.com sets no cookies. The cookies are:

CookiePurposeHow long
Session cookie (__Host-curae.session)Keeps you signed inUntil your session ends (at most 12 hours)
Sign-in flow cookies (__Host-curae.auth-binding, __Host-curae.social-link, __Host-curae.social-signup, __Host-curae.signup-session, __Host-curae.developer-signup-session)Protect a sign-in or sign-up while it is in progressFrom 5 minutes to 1 hour; each stops working on our servers within 1 hour
Account-area preference (__Host-curae.active-tenant)Remembers which account area you are viewing30 days
Curae Connect session (__Host-curae.connect-session)Links a Curae Connect screen to the connection you are makingUp to 30 minutes
Share-code viewer (__Host-curae.share-viewer)Lets a person who viewed a share code skip the emailed code on this browser, only if they chose "Remember me"30 days

Our sign-in system at auth.curaeai.com may also set cookies needed to complete a sign-in.

11.2. Storage in your browser. The Service also stores some information in your browser: your display theme, whether you dismissed the offer to add a passkey, information that keeps your sessions consistent across tabs, an encrypted copy of parts of your records that makes pages load faster, and, for the open tab only, where to return after you sign in, an invitation or share link you opened before signing in, notices you dismissed, and, on the page where someone views a share code, a fingerprint of a code already viewed in that tab and the name of the person who showed it, as they chose to be named. The copy of your records is encrypted with a key derived from your account; the Service does not use a copy older than 24 hours, and deletes it when you sign out.

11.3. No analytics. We do not use product analytics or any analytics service, and we set no analytics, advertising or other cookies beyond those in Section 11.1. We use the records of your requests described in Section 4.6 only to secure and operate the Service and to meet our legal obligations.

11.4. No advertising. We do not use advertising cookies, tracking pixels or social-media plug-ins, and we do not allow others to collect information about your activity on the Service for advertising.

11.5. Browser privacy signals. We do not sell or share personal information for targeted advertising, and we use no analytics, so there is nothing for a Global Privacy Control or "Do Not Track" signal from your browser to turn off.

12. Adults only

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18 through an account, and we do not connect an account to a health record that shows, or may show, that the person is under 18. If a record we already connected later shows that the person is under 18, we disconnect it, end every share and app access that reads it, delete it, and tell the account holder in the Service and by email. If we learn that someone under 18 has created an account, we close it. If you believe a child has given us information, contact privacy@curaeai.com.

13. If there is a breach

If there is a breach of the security of your health information, we notify you as the FTC Health Breach Notification Rule and applicable state laws require: without unreasonable delay and in any case within the time those laws allow, by email to the address on your account together with a notice in the Service, telling you what happened, what information was involved, what we are doing, and what you can do. Where those laws require it, we also notify the Federal Trade Commission, state authorities and the media. If your account was made through Curae Connect and you have not finished setting up a full account, we have no email address for you: the app you used delivers our notice to you on our behalf, by email and inside the app, and where the law requires it we also post the notice on our website with a toll-free number.

14. State privacy disclosures

14.1. Categories of personal information (including for California residents)

We collect the following categories of personal information. For each, the sources, our purposes and the recipients are described in Sections 4 to 6, and how long we keep it in Section 9. We do not sell personal information or share it for cross-context behavioral advertising, and we have never done so, including for anyone under 16.

CategoryExamplesDisclosed for a business purpose to
IdentifiersName, email address, phone number, account and device identifiers, IP address, identifiers in your recordsService providers; people and apps you direct
Personal information described in California Civil Code § 1798.80(e)Name, address, phone number, insurance information and medical informationService providers; people and apps you direct
Characteristics of protected classificationsAge and date of birth, sex, race, ethnicity, ancestry, marital status, sexual orientation, health conditionsService providers; people and apps you direct
Internet or other electronic network activityRecords of requests and actions in the ServiceService providers
Audio, electronic or visual informationYour profile photo; images and documents you upload or importService providers; people and apps you direct
Professional or employment-related informationOccupation you add to your profile; a developer's organizationService providers
Education informationEducation level you add to your profileService providers
InferencesCalculated health scores and estimatesService providers; people and apps you direct
Sensitive personal informationAccount sign-in credentials; health information; racial or ethnic origin; sexual orientation; genetic information in your recordsService providers; people and apps you direct

Sensitive personal information. We use and disclose sensitive personal information only to provide the Service you request, to keep it secure, to meet our legal obligations and for the other purposes California's regulations permit without an opt-out, so we do not offer a separate right to limit its use.

California medical information. California treats a business that offers software designed to maintain medical information for consumers as a provider of health care under the Confidentiality of Medical Information Act. We disclose your medical information only as you direct through the Service, under the authorization you sign for each share, to our service providers, or as that Act otherwise permits.

"Shine the Light." We do not disclose personal information to third parties for their direct-marketing purposes.

14.2. Consumer health data (Washington, Nevada, Connecticut and other states)

Our Consumer Health Data Privacy Policy describes the consumer health data we collect, why, from where and with whom it is shared, and how to exercise your rights under consumer-health-data laws. We collect consumer health data only with your consent (the Consent to Collect Consumer Health Data) or as necessary to provide the Service you request.

14.3. Nevada

We do not sell covered information as Nevada law (NRS Chapter 603A) defines it. You may still send a request not to sell to privacy@curaeai.com, and we confirm it.

14.4. Other states

The rights in Section 8 are available to every user, including residents of states whose comprehensive privacy laws grant rights to access, correct, delete and obtain a copy of personal information and to appeal. We process sensitive data, including health information, only with your consent or as necessary to provide the Service you request.

15. Changes to this Privacy Policy

We may update this Privacy Policy. Each version is published with its effective date, and earlier versions remain available. When we make a material change, we tell you by email and in the Service before it takes effect and ask you to review the new version. We use personal information we already hold in a materially different way only with your consent.

16. Contact us

Email privacy@curaeai.com with any question or request about this Privacy Policy or your personal information. Don't include health information in an email to us; to see, share or delete your records, sign in and use the Service. CuraeAI Inc. operates online and answers privacy questions and requests by email.